WHY CYBERSECURITY GOVERNANCE MATTERS | INTERNAL AUDIT DEPARTMENT audit
» ARTICLE » WHY CYBERSECURITY GOVERNANCE MATTERS

WHY CYBERSECURITY GOVERNANCE MATTERS

Article Search By : Nurrul Syakira Bakhtiar | Accountant | Internal Audit Division UPM

 

The increasing prevalence of cyber threats has made cybersecurity governance a critical priority, particularly in the public sector. Cyber incidents can disrupt operations and potentially affect essential service delivery, public safety, and public trust.

Effective governance should ensure that cyber risks are managed systematically through clear accountability, decision-making structures, risk ownership, mitigation plans, and oversight mechanisms.

 

Key Challenges in the Public Sector

Public sector organisations often face several challenges that can weaken cybersecurity governance, including:

  • Legacy technology systems that remain in use despite outdated security controls.
  • Fragmented oversight structures, which may lead to inconsistent policies and unclear responsibilities.
  • Resource and talent constraints, particularly in securing sufficient cybersecurity expertise.

These challenges make clear roles, responsibilities, and management oversight increasingly important.

 

The Role of Internal Audit

Internal audit plays an important role in assessing whether cybersecurity governance structures are appropriately designed and operating as intended. The focus should not be limited to technology, but should also consider how cyber risks, responsibilities, and information are managed across the organisation.

Key areas of attention include:

  • Strategy and policies
    Ensuring that cybersecurity strategies, objectives, policies, and procedures are established and periodically updated.
  • Roles and accountability
    Ensuring that responsibilities and risk ownership are clearly defined and supported by personnel with the appropriate knowledge and competencies.
  • Stakeholder engagement
    Cyber risks should be discussed with senior management, process owners, risk management, human resources, legal, compliance, and vendors—not only the information technology function.

 

Assessing Actual Implementation

The existence of policies and organisational structures alone is not sufficient. Internal audit should also assess whether actual practices are consistent with documented responsibilities.

Interviews and walkthroughs with relevant stakeholders can help identify gaps between policy and practice. This is particularly important because the true owner of a cyber risk may not always be the information technology function, especially where the risk relates to data, operational processes, or responsibilities held by other departments.

 

Risk Management and Reporting

Good governance also depends on how risks are identified, assessed, and monitored. Internal audit can evaluate whether:

  • cyber vulnerabilities and risks are identified regularly;
  • mitigation actions have clear ownership and timelines; and
  • management receives accurate and timely information.

Dashboards, key performance indicators, incident reports, and compliance updates are among the key sources of information that support effective management decision-making.

 

The Human Element Matters Too

Cybersecurity is not solely a technology issue. Awareness, competency, communication, and clarity of human responsibilities also play an important role in ensuring that controls operate effectively.

Overall, effective cybersecurity governance requires a combination of clear structures, defined risk ownership, continuous oversight, and reliable information. Through systematic assessment, internal audit can help organisations identify governance gaps, strengthen accountability, and improve the effectiveness of cyber risk management.

 

Source: “Why Cybersecurity Governance Matters” oleh Logan Wamsley. | Laman web: https://internalauditor.theiia.org

Date of Input: 27/08/2026 | Updated: 27/08/2026 | faiz_suparman

MEDIA SHARING

INTERNAL AUDIT DEPARTMENT
Universiti Putra Malaysia
43400 UPM Serdang
Selangor Darul Ehsan
03-9769 1346
03-9769 6176
X, (09:07:40pm-09:12:40pm, 23 Sep 2026)   [*LIVETIMESTAMP*]